Show filters
62 Total Results
Displaying 51-60 of 62
Sort by:
Attacker Value
Unknown
CVE-2019-13569
Disclosure Date: July 19, 2019 (last updated November 27, 2024)
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
0
Attacker Value
Unknown
CVE-2019-19985
Disclosure Date: February 28, 2019 (last updated November 27, 2024)
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
0
Attacker Value
Unknown
CVE-2018-0602
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-6015
Disclosure Date: January 26, 2018 (last updated November 26, 2024)
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data.
0
Attacker Value
Unknown
CVE-2017-18010
Disclosure Date: January 01, 2018 (last updated November 26, 2024)
The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
0
Attacker Value
Unknown
CVE-2014-3907
Disclosure Date: August 26, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown
CVE-2014-4725
Disclosure Date: July 27, 2014 (last updated October 05, 2023)
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
0
Attacker Value
Unknown
CVE-2014-4726
Disclosure Date: July 27, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.
0
Attacker Value
Unknown
CVE-2014-4527
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin before 1.98 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) FormID or (2) AdministratorID parameter.
0
Attacker Value
Unknown
CVE-2013-1408
Disclosure Date: March 24, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.
0